Home/Catalog/CISCO-L2NAT-MIB

CISCO-L2NAT-MIB

AI MIB Summary

The CISCO-L2NAT-MIB monitors and configures Layer 2 Network Address Translation instances on Cisco Industrial Ethernet switches utilizing FPGA-based uplink processing, specifically tracking per-instance packet fixups, source/destination IP translation rules, and interface-VLAN binding statistics. It provides granular visibility into global platform counters, instance-specific permit/deny flows, and traffic statistics for packets traversing uplinks, enabling the management of embedded IP address translation within Layer 2 switched environments.

Network Address Translation (NAT) involves translating the source and or destination IP addresses of packets as they traverse from one IP domain to another. NAT is usually performed on packets that are routed, and there is a MIB already defined for that, but the application addressed here is for performing NAT for Layer 2 switched packets. This MIB module defines objects and tables for Network Address Translation (NAT) performed at layer 2. This application is planned currently for Industrial Ethernet switches, but this could be used for other applications. This platform implements NAT using an FPGA which connects to uplinks, so NAT is only applicable for packets coming in from uplinks, and going out of uplinks. There are 3 main logical modules that are referred in this MIB. Global parameters : These provide statistics for the entire platform. L2NAT Instance Table : This table contains multiple Layer 2 NAT instances. A Layer 2 NAT instance referred throughout this MIB is an entity that is defined with respect to the Layer 2 NAT feature, and is different from the concept of instance as used in SNMP. Each Layer 2 NAT instance has a unique number. Each Layer 2 NAT instance consists of packets that are to be permitted or denied, as well as packets that are supposed to be fixed up. Fixup is a NAT concept which applies to certain applications which embed IP addresses in the payload. For these applications to work across NAT, the embedded IP addresses need to be translated along with the header IP addresses. Each Layer 2 NAT instance also contains a list of source and/or destination IP address translations An instance only becomes effective on traffic after being applied to an interface vlan combination. This table actually consists of these 2 MIB tables in order for indexing to work, cl2natInstanceTable and cl2natInstanceIpTable L2NAT Interface Config Table : This table contains multiple entries, where each entry contains configuration for the instance applied to an interface vlan combination. This table actually consists of these 2 MIB tables in order for indexing to work cl2natInterfaceConfigTable and cl2natInterfaceIpConfigTable. L2NAT Interface Statistics Table : This table contains multiple entries, where each entry contains stats for the instance applied to an interface vlan combination. This table actually consists of these 2 MIB tables in order for indexing to work , cl2natInterfaceStatisticsTable and cl2natInterfaceIpStatisticsTable.
Main OID:
ciscoL2natMIB.1.3.6.1.4.1.9.9.806
76
Objects
Active
Status
7
Dependencies

Imported Objects

Objects

76 total
Object Name
ciscoL2natMIBNetwork Address Translation (NAT) involves translating the source and or destination IP addresses of packets as they traverse from one IP domain to another. NAT is usually performed on packets that are routed, and there is a MIB already defined for that, but the application addressed here is for performing NAT for Layer 2 switched packets. This MIB module defines objects and tables for Network Address Translation (NAT) performed at layer 2. This application is planned currently for Industrial Ethernet switches, but this could be used for other applications. This platform implements NAT using an FPGA which connects to uplinks, so NAT is only applicable for packets coming in from uplinks, and going out of uplinks. There are 3 main logical modules that are referred in this MIB. Global parameters : These provide statistics for the entire platform. L2NAT Instance Table : This table contains multiple Layer 2 NAT instances. A Layer 2 NAT instance referred throughout this MIB is an entity that is defined with respect to the Layer 2 NAT feature, and is different from the concept of instance as used in SNMP. Each Layer 2 NAT instance has a unique number. Each Layer 2 NAT instance consists of packets that are to be permitted or denied, as well as packets that are supposed to be fixed up. Fixup is a NAT concept which applies to certain applications which embed IP addresses in the payload. For these applications to work across NAT, the embedded IP addresses need to be translated along with the header IP addresses. Each Layer 2 NAT instance also contains a list of source and/or destination IP address translations An instance only becomes effective on traffic after being applied to an interface vlan combination. This table actually consists of these 2 MIB tables in order for indexing to work, cl2natInstanceTable and cl2natInstanceIpTable L2NAT Interface Config Table : This table contains multiple entries, where each entry contains configuration for the instance applied to an interface vlan combination. This table actually consists of these 2 MIB tables in order for indexing to work cl2natInterfaceConfigTable and cl2natInterfaceIpConfigTable. L2NAT Interface Statistics Table : This table contains multiple entries, where each entry contains stats for the instance applied to an interface vlan combination. This table actually consists of these 2 MIB tables in order for indexing to work , cl2natInterfaceStatisticsTable and cl2natInterfaceIpStatisticsTable.
MODULE-IDENTITY
.1.3.6.1.4.1.9.9.806
ciscoL2natMIBObjects
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.806.1
cl2natTotalInstancesThis object indicates the total number of Instances defined by the user on this device. Each instance is an independent module of configuration including IP address translations that only becomes active after being applied to an interface/vlan combination.ro
Counter32
.1.3.6.1.4.1.9.9.806.1.1
cl2natTotalMatchedThis object indicates the number of times a packet matches with user configured IP translation entries. It should be noted that the same packet can be counted twice if it matches both the outside and inside entries, one for the source address translation, and the other for the destination address translation.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.2
cl2natTotalUnmatchedThis object indicates the total number of packets that did not match any of the configured NAT entries.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.3
cl2natTotalFixupsThis object indicates the total number of packets that required fixups.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.4
cl2natTotalTranslationEntryConfiguredThis object specifies the total number IP translation entries currently configured in the system.ro
Unsigned32
.1.3.6.1.4.1.9.9.806.1.5
cl2natTotalPacketTranslatedThis object indicates the total number of packets that got translated per rules defined in the cl2natinstanceIpTablero
Counter64
.1.3.6.1.4.1.9.9.806.1.6
cl2natInstConfigInstanceTableThis table contains multiple Layer 2 NAT instances. Each Layer 2 NAT instance has a unique name and consists of configurations other than the list of IP NAT translations for which there is a separate table. An instance only becomes effective on traffic after being applied to an interface/vlan combination, which is done through the cl2natInterfaceConfigTable.
SEQUENCE OF Cl2natInstConfigInstanceEntry
.1.3.6.1.4.1.9.9.806.1.7
cl2natInstConfigInstanceEntryThis entry is created as a row in the cl2natInstConfigInstanceTable table when a user configures a new instance. Each entry consists of the configuration parameters described below, and is indexed by the Layer 2 NAT instance name.
Cl2natInstConfigInstanceEntry
.1.3.6.1.4.1.9.9.806.1.7.1
cl2natInstConfigInstanceNameThis object specifies the Name assigned by user to a created Layer 2 NAT instance.
SnmpAdminString
.1.3.6.1.4.1.9.9.806.1.7.1.1
cl2natInstConfigPermitInThis object specifies user configured options for permitting or denying packets coming in from uplinks that do not match any NAT entry (unmatched), IGMP packets, multicast packets. A bit value of 0 denotes drop and a value of 1 indicates permit for that type. Default is 'drop' for all 3 types.rw
Bits
.1.3.6.1.4.1.9.9.806.1.7.1.2
cl2natInstConfigPermitOutThis object specifies user configured options for permitting or denying packets going out of uplinks that do not match any NAT entry (unmatched), IGMP packets, multicast packets. A bit value of 0 denotes drop and a value of 1 indicates permit for that type. Default is drop for all 3 types.rw
Bits
.1.3.6.1.4.1.9.9.806.1.7.1.3
cl2natInstConfigFixupThis object specifies user configured options for fixing up ARP, ICMP, Profinet, CIP and SNMP protocols. A fixup is required for protocols which embed IP addresses to work across NAT boundaries, and involves translating any IP address embedded in the protocol payload to the corresponding configured translated address. A bit value of 1 denotes fixup is enabled for that protocol, and a value of 0 indicates fixup is disabled. By default, fixup is enabled for ARP, ICMP, Profinet and CIP (if required).rw
Bits
.1.3.6.1.4.1.9.9.806.1.7.1.4
cl2natInstConfigStorageTypeThis object specifies the storage type for this conceptual row. The following columnar objects are allowed to be writable when the storageType of this conceptual row is permanent(4): (replace with list of columns)ro
StorageType (SNMPv2-TC)
.1.3.6.1.4.1.9.9.806.1.7.1.5
cl2natInstConfigInstanceRowStatusThis object will follow RowStatus Textual convention to create/destroy entries. The following columnar objects are mandatory to make the entry 'active': cl2natInstIpInstanceName Once the entry status has been set to active(1), the entry cannot be modified. The only operation possible after this is to delete the entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.9.9.806.1.7.1.6
cl2natInstIpInstanceIpTableThis table consists of multiple IP entries for each Layer2 NAT instances. This table is a logical extension of the cl2natInstInstanceTable because it is linked to the same Layer 2 NAT instance. This table is required because there can be multiple address translation entries for the same Layer 2 NAT instance.
SEQUENCE OF Cl2natInstIpInstanceIpEntry
.1.3.6.1.4.1.9.9.806.1.8
cl2natInstIpInstanceIpEntryThis Entry is created when a new IP translation entry is added for a particular instance.
Cl2natInstIpInstanceIpEntry
.1.3.6.1.4.1.9.9.806.1.8.1
cl2natInstIpDirectionThis object specifies the direction in which an address is to be translated. A value of 1 denotes that this entry is for translating source IP address of packets going out of uplinks, or destination IP address of packets coming in. A value of 2 denotes that this entry is for translating destination IP address of packets going out of uplinks, or source IP address of packets coming in.
Enumeration
.1.3.6.1.4.1.9.9.806.1.8.1.1
cl2natInstIpAddressTypeThis object specifies the type of address that is used to configure this translation. 'host' implies that this is a single IP address translation for one host. 'range' implies that the cl2natFromAddress and cl2natToAddress are the starting addresses of the range, and the cl2natIpRange is the number of addresses that are translated with this single config. 'network' implies that an entire class C network of original IP addresses is translated to the corresponding 254 address starting from the cl2natToAddress.
Enumeration
.1.3.6.1.4.1.9.9.806.1.8.1.2
cl2natInstIpFromIpAddressTypeThe address type of cl2natFromIpAddress. This object specifies whether this translation is for for IPv4 or IPv6.
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.9.9.806.1.8.1.3
cl2natInstIpFromIpAddressThis object indicates the source IP address of packets going out of the uplink before translation if the cl2natInstIpDirection value for this entry is inside(1). This objects indicate the destination IP address of packets coming in from the uplinks after translation if the cl2natInstIpDirection value for this entry is outside(2)
InetAddress
.1.3.6.1.4.1.9.9.806.1.8.1.4
cl2natInstIpToIpAddressTypeThe address type of cl2natInstIpToIpAddress. This object specifies whether this translation is for for IPv4 or IPv6.rw
InetAddressType (INET-ADDRESS-MIB)
.1.3.6.1.4.1.9.9.806.1.8.1.5
cl2natInstIpToIpAddressThis object indicates the Source IP address of packets going out of the uplink after translation, and destination IP address of packets coming in from the uplinks before translation if the cl2natInstIpDirection value for this entry is inside(1), or the Destination IP address of packets going out of the uplink after translation, and source IP address of packets coming in from the uplinks before translation if the cl2natInstIpDirection value for this entry is outside(2).rw
InetAddress
.1.3.6.1.4.1.9.9.806.1.8.1.6
cl2natInstIpAddressMaskThis object specifies the subnet address mask when the value of cl2natInstIpAddressType is 'network'. This is not used for any other option.rw
CiscoInetAddressMask (CISCO-TC)
.1.3.6.1.4.1.9.9.806.1.8.1.7
cl2natInstIpRangeThis object specifies the number of addresses to be translated in case the value of cl2natIpAddressType is 'range'. This is not used for any other option.rw
Integer32
.1.3.6.1.4.1.9.9.806.1.8.1.8
cl2natInstStorageIpStorageTypeThis object specifies the storage type for this conceptual row. The following columnar objects are allowed to be writable when the storageType of this conceptual row is permanent(4): (replace with list of columns)ro
StorageType (SNMPv2-TC)
.1.3.6.1.4.1.9.9.806.1.8.1.9
cl2natInstIpRowStatusThis object will follow RowStatus Textual convention to create/destroy entries. The following columnar objects are mandatory to make the entry 'active': cl2natInstIpDirection cl2natInstIpFromIpAddress cl2natInstIpToIpAddress Once the entry status has been set to active(1), the entry cannot be modified. The only operation possible after this is to delete the entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.9.9.806.1.8.1.10
cl2natInterfaceConfigTableThis table contains multiple entries, where each entry contains configuration of the instance applied to an interface/vlan combination.
SEQUENCE OF Cl2natInterfaceConfigEntry
.1.3.6.1.4.1.9.9.806.1.9
cl2natInterfaceConfigEntryEach Entry is created as a row in the cl2natInterfaceConfigTable table when a user applies an instance to an interface/vlan combination, and removed when that instance is removed. A value of 0 in cl2natInterfaceVlanIndex indicates that this attachment is for untagged traffic. The result of this lookup is actually an index that is used to lookup the cl2natInstanceTable which gives the actual config of the instance attached.
Cl2natInterfaceConfigEntry
.1.3.6.1.4.1.9.9.806.1.9.1
cl2natInterfaceConfigIfIndexThe index value that uniquely identifies the interface to which this entry is applicable. The interface identified by a particular value of this index is the same interface as identified by the same value of the IF-MIB's ifIndex.
Unsigned32
.1.3.6.1.4.1.9.9.806.1.9.1.1
cl2natInterfaceConfigVlanIndexThis object indicates the vlan ID the L2NAT instance is attached to. A value of 0 indicates the instance is attached to untagged traffic of the interface.
Unsigned32
.1.3.6.1.4.1.9.9.806.1.9.1.2
cl2natInterfaceConfigInstanceNameThis object indicates the Layer 2 NAT Instance Name to be looked up to retrieve its configuration details. This name corresponds to what's in cl2natInstConfigInstanceNamero
SnmpAdminString
.1.3.6.1.4.1.9.9.806.1.9.1.3
cl2natInterfaceConfigStorageTypeThis object specifies the storage type for this conceptual row. The following columnar objects are allowed to be writable when the storageType of this conceptual row is permanent(4): (replace with list of columns)ro
StorageType (SNMPv2-TC)
.1.3.6.1.4.1.9.9.806.1.9.1.4
cl2natInterfaceConfigRowStatusThis object will follow RowStatus Textual convention to create/destroy entries. The following columnar objects are mandatory to make the entry 'active': ifIndex Once the entry status has been set to active(1), the entry cannot be modified. The only operation possible after this is to delete the entry.rw
RowStatus (SNMPv2-TC)
.1.3.6.1.4.1.9.9.806.1.9.1.5
cl2natInterfaceStatisticsTableThis table contains the Layer 2 NAT instance level statistics. The IP address translation statistics are contained in the cl2natInterfaceIpStatisticsTable.
SEQUENCE OF Cl2natInterfaceStatisticsEntry
.1.3.6.1.4.1.9.9.806.1.10
cl2natInterfaceStatisticsEntryThis Entry is created as a row in the cl2natInterfaceStatisticsTable table when a user applies an instance to an interface/vlan combination, and removed when that instance is removed.
Cl2natInterfaceStatisticsEntry
.1.3.6.1.4.1.9.9.806.1.10.1
cl2natFixupArpInThis object indicates the Number of fixed up ARP packets for this Layer 2 NAT Instance coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.1
cl2natFixupIcmpInThis object indicates the Number of fixed up ICMP packets for this Layer 2 NAT Instance coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.2
cl2natFixupCipInThis object indicates the Number of fixed up CIP packets for this Layer 2 NAT Instance coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.3
cl2natFixupProfinetInThis object indicates the Number of fixed up Profinet packets for this Layer 2 NAT Instance coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.4
cl2natFixupFtpInThis object indicates the Number of fixed up FTP packets for this Layer 2 NAT Instance coming into the uplinksk.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.5
cl2natFixupSnmpInThis object indicates the Number of fixed up SNMP packets for this Layer 2 NAT Instance coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.6
cl2natFixupSipInThis object indicates the Number of fixed up Sip packets for this Layer 2 NAT Instance coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.7
cl2natFixupSccpInThis object indicates the Number of fixed up Sccp packets for this Layer 2 NAT Instance coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.8
cl2natUnmatchedInThis object indicates the Number of unmatched packets for this Layer 2 NAT Instance coming into the uplinks. 'Unmatched' packets are those that do not match any IP address translation configured for this layer 2 NAT instance.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.9
cl2natTranslatedUnicastInThis object indicates the Number of translated unicast packets for this Layer 2 NAT coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.10
cl2natDroppedUnicastInThis object indicates the Number of Dropped unicast packets for this Layer 2 NAT instance coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.11
cl2natDroppedMulticastInThis object indicates the Number of dropped multicast packets for this Layer 2 NAT coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.12
cl2natPassThruUnicastInThis object indicates the Number of passed through unicast packets for this Layer 2 NAT coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.13
cl2natPassThruMulticastInThis object indicates the Number of passed through multicast packets for this Layer 2 NAT coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.14
cl2natPassThruIgmpInThis object indicates the Number of passed through IGMP packets for this Layer 2 NAT coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.15
cl2natDroppedIgmpInThis object indicates the Number of dropped IGMP packets for this Layer 2 NAT coming into the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.16
cl2natFixupArpOutThis object indicates the Number of fixed up ARP packets for this Layer 2 NAT Instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.17
cl2natFixupIcmpOutThis object indicates the Number of fixed up ICMP packets for this Layer 2 NAT Instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.18
cl2natFixupCipOutThis object indicates the Number of fixed up CIP packets for this Layer 2 NAT Instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.19
cl2natFixupProfinetOutThis object indicates the Number of fixed up Profinet packets for this Layer 2 NAT Instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.20
cl2natFixupFtpOutThis object indicates the Number of fixed up FTP packets for this Layer 2 NAT Instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.21
cl2natFixupSnmpOutThis object indicates the Number of fixed up SNMP packets for this Layer 2 NAT Instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.22
cl2natFixupSipOutThis object indicates the Number of fixed up Sip packets for this Layer 2 NAT Instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.23
cl2natFixupSccpOutThis object indicates the Number of fixed up Sccp packets for this Layer 2 NAT Instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.24
cl2natUnmatchedOutThis object indicates the Number of unmatched packets for this Layer 2 NAT Instance going out of the uplinks. 'Unmatched' packets are those that do not match any IP address translation configured for this layer 2 NAT instance.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.25
cl2natDroppedUnicastOutThis object indicates the Number of Dropped unicast packets for this Layer 2 NAT instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.26
cl2natTranslatedUnicastOutThis object indicates the Number of translated unicast packets for this Layer 2 NAT going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.27
cl2natPassThruUnicastOutThis object indicates the Number of passed through unicast packets for this Layer 2 NAT instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.28
cl2natDroppedMulticastOutThis object indicates the Number of dropped multicast packets for this Layer 2 NAT instance going out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.29
cl2natPassThruMulticastOutThis object indicates the Number of passed through multicast packets for this Layer 2 NAT coming out the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.30
cl2natDroppedIgmpOutThis object indicates the Number of dropped IGMP packets for this Layer 2 NAT coming out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.31
cl2natPassThruIgmpOutThis object indicates the Number of passed through IGMP packets for this Layer 2 NAT coming out of the uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.10.1.32
cl2natInterfaceIpStatisticsTableThis table contains statistics for IP translations of an L2 NAT instance that is applied to interface/vlan combination. This table is a logical extension of the cl2natInterfaceStatisticsTable, because these translations belong to the same instance referred to in that table.
SEQUENCE OF Cl2natInterfaceIpStatisticsEntry
.1.3.6.1.4.1.9.9.806.1.11
cl2natInterfaceIpStatisticsEntryThis Entry is created in the cl2natInterfaceIpStatisticsTable for each IP translation of a Layer 2 NAT instance when it is attached to an interface/vlan.
Cl2natInterfaceIpStatisticsEntry
.1.3.6.1.4.1.9.9.806.1.11.1
cl2natTranslatesInThis entry specifies the number of times this entry was matched for packets going from inside to outside of uplinks.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.11.1.1
cl2natTranslatesOutThis entry specifies the number of times this entry was matched for packets coming in from outside of uplinks to inside.ro
Counter64
.1.3.6.1.4.1.9.9.806.1.11.1.2
ciscoL2natMIBConformance
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.806.3
ciscoL2natMIBCompliances
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.806.3.1
ciscoL2natMIBGroups
OBJECT IDENTIFIER
.1.3.6.1.4.1.9.9.806.3.2
CISCO-L2NAT-MIB - SNMP MIB Reference | MIBs Explorer